Weak networks need NAC bypass

Confusion reigns due to lack of clear definitions

Written by Martin Courtney

The majority of current network access control (NAC) solutions fail to address basic security problems, and the proprietary approach adopted by Cisco, Microsoft and the Trusted Computing Group is blocking the development of a certified, interoperable NAC standard.

Ofir Arkin, chief technology officer (CTO) at network security specialist Insightix, says that the lack of a clear definition of what NAC is and does is confusing potential customers, and allowing vendors to tag the NAC label onto a broad range of products that do not merit the description.

Host admission control schemes are designed to protect enterprise networks by allowing or denying network access to PCs, laptops and other devices based on the health and security status of those machines.

The best-known examples are Cisco’s Network Access Control (NAC), Microsoft’s Network Access Protection (NAP), and the TCG’s Trusted Network Connect (TNC), but a host of other software vendors are jumping on the NAC bandwagon, including Symantec and Sygate.

‘Each of the Cisco, Microsoft and TCG initiatives are trying to put more and more companies onto their approach, rather than thinking about how to work out a mutual standard or work together,’ said Arkin.

‘Cisco concluded in 2003 about how NAC should work, but you can call anything a NAC solution – the problem is what it is doing and whether it has the type of components that a NAC solution should have.’

Arkin says most NAC solutions fall at the first hurdle through their inability to keep real time conceptual information about the network, which means that any element is allowed to operate without intervention.

Another problem is that the 802.1x security measures only enforce usernames and passwords for computers, and not printers, IP telephone handsets, cameras or wireless access points, leaving them open to have their MAC addresses discovered and re-used by hackers.

‘Many companies are looking for a silver bullet that does everything in terms of network security and management, but this does not exist. NAC is one important piece of an internal network security infrastructure, but you need to understand its capabilities and its limits, and what it actually provides,’ added Arkin.

Tags:

reader comments

related articles

Juniper NAC system is out

Unified Access Control network access control from Jupiter integrates Funk Soft tech 13 Nov 2006

 

Extreme closes NAC loophole

Network specialist Extreme announces upgrades to switch firmware 29 Jan 2007

Sophos targets network access control

Security vendor Sophos has bought US network access control specialist Endforce 15 Jan 2007

Cisco updates security systems

NAC upgrade and two new security appliances provide single sign on and validation of user identities. 17 Jul 2006

NAP to be ‘kicked out’ of Vista

Microsoft’s Network Access Protection tools could be removed for being too complex 29 Sep 2006

AEP NACpoint appliance guards network access

AEP says the kit can work seamlessly with Cisco, Enterasys, Extreme, HP and 3Com managed network switches 19 Sep 2006

Appliances bolster access control

SC Safeword SecureWire devices deliver unified threat management 01 May 2006

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats 14 Nov 2007

Experts talk up enterprise voice over Wi-Fi

Enterprises will embrace the technology ... eventually 19 Dec 2007

Juniper upgrades network access protection

Juniper updates its line of unified access control tools 04 Aug 2008

related whitepapers

today's top stories

Body Shop rolls out PCI system

Retailer hopes to benefit from improved customer data analysis 07 Oct 2008

Where to offshore (and why not here?)

Tholons, the research firm founded by well-known offshoring guru Avinash Vashistha , has just published some new research in Global Services magazine... 07 Oct 2008

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

The pIT stop Q&A: How can I measure the business success of IT applications?

Ou expert panel answers readers' real-life IT questions 07 Oct 2008

National Identity Fraud Prevention Week

Every Monday seems to mark the beginning of a new awareness drive and this week’s theme has particular importance to small businesses... 06 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

Ethernet cableVideo

The future of Ethernet

Where is Ethernet going? We look at the future of the widely-used networking technology. 07 Oct 2008

Podcast imageAudio

Computing podcast - Next-generation broadband Britain; and we report from Gartner's IT security summit

In our latest podcast, we discuss the hurdles that a national fibre-optic network must overcome, and look at the issues discussed at the recent IT security conference 02 Oct 2008

Latest in-depth articles

Features

How to ensure progress in programming

Best practice advice from Forrester Research 02 Oct 2008

BT workersAnalysis

Wanted: a viable model for fibre

While other European countries are pressing ahead with fibre rollouts, progress in the UK is being held back as the debate over who will foot the bill drags on, writes Dave Bailey 02 Oct 2008

Advertisement

Primary Navigation